Cyber Incident Response in Kenya: A Practical Guide for Businesses

A ransom note on the screen. Systems down. Phones ringing. What a business does in the first day of a cyber incident shapes its legal position for months afterwards , and panic is not a plan.

Kenyatta International Convention Centre in Nairobi
Photo: Francis Akuka for the Wikimedia Foundation (CC0), via Wikimedia Commons

What should the first hours of a cyber incident look like?

  • Isolate affected systems to stop the spread, but preserve logs and evidence before anything is wiped.
  • Activate the response team: IT, management, communications and legal.
  • Establish what data and systems are involved, and whether personal data is affected.
  • Engage forensic specialists, and keep a single record of decisions and timings.

Who must be told?


Where a cyber incident involves a personal data breach, the Data Protection Act 2019 requires notification to the Office of the Data Protection Commissioner without undue delay and, in serious cases, notification of the affected individuals. Where unauthorised access to a computer system is suspected, the Computer Misuse and Cybercrimes Act 2018 is engaged and a report to law enforcement may be appropriate; the statute is available on Kenya Law. Banks, insurers and large customers may also have notification requirements under their own contracts, so those documents should be checked early.

Notification is not an admission of fault; it is a duty in defined situations. Deciding whether the threshold is met , and documenting the reasoning , is part of the response, and deserves deliberation rather than guesswork.

How do you prepare before anything happens?

Response is easier with groundwork: an incident plan with named roles, supplier contracts that require prompt cooperation, tested backups and a notification workflow. Businesses that have already mapped their data assess incidents far faster. A governance review of cyber readiness , policies, vendor terms and escalation paths , is a reasonable investment before, not after, an incident; see our governance advisory services. Vendor and customer contracts should be checked for notification windows and cooperation duties; our contract lawyers can assist. Where customers or partners threaten claims afterwards, the dispute-resolution clauses in those contracts usually determine the forum , see our arbitration and ADR practice.

For guidance on your specific situation, contact CS Advocates LLP , call, WhatsApp, or book a confidential consultation at our Westlands, Nairobi office.

Leave a Comment

Your email address and phone number are for verification only and will never be published. Comments appear after approval by the firm. Ask a question anonymously if you prefer.

+254 728 293 000 Email us +254 20 80 93 000 Confidential consultation